Reduce direct RDP exposure first
Where possible, put RDP behind VPN, Remote Desktop Gateway, trusted network restrictions or another controlled access path. Guard adds host-level evidence and response for environments where RDP-related authentication remains reachable.
Use authentication events, not port assumptions
Guard monitors supported Windows authentication evidence rather than treating one TCP port as the whole application. That matters because RDP, RemoteApp and RDWeb can involve different Windows and IIS event paths. The collector needs enough context to identify the source and reason safely.
Do not compensate for aggressive thresholds with huge whitelists
A common design mistake is to block very quickly and then whitelist entire networks to reduce disruption. That creates blind spots. A better model combines realistic thresholds, explicit trust, successful-login learning and monitor-specific tuning.
Test RDWeb and RemoteApp after configuration changes
Certificates, authentication settings, proxies, gateways and IIS changes can alter what evidence is available. Generate controlled failed logins and verify that the expected source IP and username reach Guard before relying on automatic blocking.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Scantide Guard Product & Server Security GuidesProtect Windows Server from repeated RDP, IIS/RDWeb, Kerberos and SQL Server authentication attacks with deterministic monitoring and Windows Firewall blocking.
Current Scantide source: Scantide Guard for Windows ServerScantide Guard is intended for Windows Server estates ranging from Windows Server 2008 R2 SP1 through current Windows Server releases. The product family includes Windows Server 2008 R2, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022 and Windows Server 2025. Server 2008 R2 uses the Legacy Guard implementation; later Windows Server versions use the modern Guard implementation.
Current Scantide source: RDP Brute Force Protection for Windows ServerWindows Security Event ID 4625 is a common failed-logon source. Guard also supports other trusted authentication evidence depending on the configured collector.
Current Scantide source: Scantide Guard Product & Server Security GuidesScantide Guard is designed for mixed Windows Server environments including Windows Server 2008 R2 SP1, 2012 R2, 2016, 2019, 2022 and 2025. One unified Windows installer covers Guard and Datacenter, while automatically selecting Legacy Guard on Windows Server 2008 R2 SP1.
Current Scantide source: RDP Brute Force Protection for Windows ServerInternet-facing RDP services are continuously probed. Guard watches trusted Windows authentication evidence, correlates repeated failures and can block the source IP locally before it continues hammering the server.
Field experience from the archive
Historical source · JufCorp: Securing your servers, users and customers onlineUse an automatic brute force prevention software ( I can recommend you some that can block attacks on RDWeb, RDP, Exchange Webmail, FTP, Citrix., basically anything that uses Windows Authentication or help you set it up if you like)
Brute force attacks Another method of rendering you server useless is to use a brute force attack on the usernames (sometimes also known as a "dictionary attack" ) .
Historical source · JufCorp: Brute force protection on Windows ServerNow, there are other ways of taking care of this problem and one is to use a brute force prevention software (which I do )
Anyhoo.. just a short post on the matter of brute force prevention on Windows and what it can do for yu.
Practical review checklist
- Protect Windows Server from repeated RDP, IIS/RDWeb, Kerberos and SQL Server authentication attacks with deterministic monitoring and Windows Firewall blocking.
- Scantide Guard is intended for Windows Server estates ranging from Windows Server 2008 R2 SP1 through current Windows Server releases.
- Windows Security Event ID 4625 is a common failed-logon source.
- Scantide Guard is designed for mixed Windows Server environments including Windows Server 2008 R2 SP1, 2012 R2, 2016, 2019, 2022 and 2025.
- Use an automatic brute force prevention software ( I can recommend you some that can block attacks on RDWeb, RDP, Exchange Webmail, FTP, Citrix., basically anything that uses Windows Authentication or help you set it up if you like)
- Brute force attacks Another method of rendering you server useless is to use a brute force attack on the usernames (sometimes also known as a "dictionary attack" ) .
- Easy to use, cheap and it's helped protect against 185 000 live brute force attacks around the world so far.